N3 interface session management method and management system in 5g private network environment
By using a soft traffic splitting mode to parse the five-tuple information of the GTP protocol payload and recalculate the flow identifier ID in a 5G private network environment, the problem of serial processing of the same five-tuple data is solved, high-concurrency N3 interface traffic management is realized, and the processing efficiency of security devices is improved.
Patent Information
- Application Number
- CN202310073201.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-07
- Publication Date
- 2026-02-03
- Estimated Expiration
- 2043-02-07
AI Technical Summary
In 5G networks, terminal data with the same quintuple information are grouped into the same stream, causing the traffic processing engine to process data serially and not in parallel with multiple terminals.
The N3 interface traffic is processed using a soft traffic splitting mode. By parsing the five-tuple information of the GTP protocol payload, the flow identifier ID is recalculated, and the packets are distributed to the corresponding flow processing engine.
It enables high-concurrency processing of N3 traffic, improves the security device's ability to handle 5G private network traffic, and enhances security protection capabilities.
Smart Images

Figure CN116074846B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of information security, specifically relating to a method and management system for managing N3 interface sessions in a 5G private network environment. Background Technology
[0002] The architecture of 5G networks differs from that of the conventional internet. Terminal network access is divided into signaling domain and service domain. After successful terminal authentication, a tunnel for service domain data transmission is allocated. Service domain data transmission is conducted through the N3 interface, which connects the base station and the UPF network element. The N3 interface uses the GTP tunneling protocol, which can handle IP layer and higher-layer data from the terminal.
[0003] In 5G networks, a single base station transmits data from multiple terminals, and all terminal data transmissions use the GTP protocol. When multiple terminal data streams are transmitted between the same base station and UPF network element, the 5-tuple information of all terminal data streams is identical. During the research and development process, the inventors of this application discovered that in general traffic processing engines, the 5-tuple information is used as the stream ID, and identical 5-tuples are grouped into the same stream. Since these streams are grouped into the same stream, the traffic processing engine can only process the data in that stream serially, which prevents the parallel processing of all terminal data contained within that stream. Summary of the Invention
[0004] To at least partially overcome the problems existing in related technologies, this application provides a method and management system for N3 interface session management in a 5G private network environment.
[0005] According to a first aspect of the embodiments of this application, this application provides an N3 interface session management method in a 5G private network environment, which includes the following steps:
[0006] Accessing network card traffic using a soft traffic splitting mode;
[0007] The traffic from the access network interface card is parsed, including:
[0008] The network interface card (NIC) traffic is parsed using packet protocol parsing to obtain packet 5-tuple information;
[0009] Parse the GTP protocol;
[0010] The IP and transport layers of the GTP protocol payload are parsed to obtain the payload's 5-tuple information, which is then used to replace the message's 5-tuple information.
[0011] The flow identifier ID is calculated based on the 5-tuple information of the load, and the packet is assigned to the corresponding flow processing engine based on the flow identifier ID.
[0012] In the N3 interface session management method in the above-mentioned 5G private network environment, the packet five-tuple information includes source IP, destination IP, source port, destination port and transport layer protocol. For packets without corresponding source IP, destination IP, source port, destination port or transport layer protocol, the corresponding information is set to 0.
[0013] In the above-mentioned 5G private network environment N3 interface session management method, the process of parsing the GTP protocol is as follows:
[0014] The message transport layer protocol is parsed, and it is determined whether the message transport layer protocol is UDP and the destination port is 2152. If so, the message transport layer protocol is determined to be GTP protocol and GTP protocol is parsed.
[0015] In the N3 interface session management method in the above-mentioned 5G private network environment, the five-tuple information of the load includes the source IP, destination IP, source port, destination port, and transport layer protocol of the load; for GTP protocol loads, if there is no corresponding source IP, destination IP, source port, destination port, or transport layer protocol in the IP layer and transport layer, the corresponding information is set to 0.
[0016] According to a second aspect of the embodiments of this application, this application also provides an N3 interface session management system in a 5G private network environment, which includes a network card traffic collection module, a traffic parsing module, and a flow identifier ID processing module;
[0017] The network card traffic collection module is used to collect network card traffic of the device;
[0018] The traffic parsing module is used to parse the source IP, destination IP, source port, destination port, and transport layer protocol information of the traffic; it is also used to parse the GTP protocol to obtain the source IP, destination IP, source port, destination port, and transport layer protocol information of the GTP payload.
[0019] The Flow Identifier ID processing module is used to calculate the Flow Identifier ID based on the five-tuple information of the GTP payload, and to allocate the packets to the corresponding flow processing engines based on the Flow Identifier ID.
[0020] According to a third aspect of the embodiments of this application, this application also provides a storage medium storing an executable program thereon, which, when invoked, executes the N3 interface session management method in the 5G private network environment described in any of the above claims.
[0021] As can be seen from the above specific embodiments of this application, it has at least the following beneficial effects: The N3 interface session management method in the 5G private network environment provided by this application adopts a soft traffic splitting mode to process N3 interface traffic, performs tunnel stripping and recalculates the flow identifier ID according to the N3 interface traffic, and allocates the packets to the corresponding flow processing engine according to the flow identifier ID. This application can process N3 traffic at high concurrency, help security devices process 5G private network traffic at high speed, and improve security protection capabilities.
[0022] It should be understood that the above general description and the following specific embodiments are merely exemplary and illustrative, and do not limit the scope of the claims made in this application. Attached Figure Description
[0023] The accompanying drawings, which are part of the specification of this application, illustrate embodiments of the present application and are used together with the description of the specification to illustrate the principles of the present application.
[0024] Figure 1 This is a diagram of a 5G private network architecture provided in an embodiment of this application.
[0025] Figure 2 This is a schematic diagram of the GTP protocol network model provided in an embodiment of this application.
[0026] Figure 3 This is an architecture diagram of a hard-splitting traffic processing system in the existing technology.
[0027] Figure 4 A flowchart illustrating an N3 interface session management method in a 5G private network environment, as provided in this application embodiment.
[0028] Figure 5 This application provides an architecture diagram of an N3 interface session management system in a 5G private network environment. Detailed Implementation
[0029] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the spirit of the content disclosed in this application will be clearly explained below with reference to the accompanying drawings and detailed description. After understanding the embodiments of this application, any person skilled in the art can make changes and modifications based on the technology taught in this application without departing from the spirit and scope of this application.
[0030] The illustrative embodiments and descriptions provided in this application are for explaining the application, but are not intended to limit the application. Furthermore, elements / components using the same or similar reference numerals in the drawings and embodiments are used to represent the same or similar parts.
[0031] The terms “first,” “second,” etc., used in this document are not intended to specifically refer to order or sequence, nor are they used to limit this application; they are merely used to distinguish elements or operations described using the same technical terms.
[0032] The terms “include,” “including,” “have,” “contain,” etc., used in this article are all open-ended terms, meaning that they include but are not limited to.
[0033] The term "and / or" as used herein includes any or all of the things mentioned.
[0034] The term "multiple" in this article includes "two" and "more than two"; the term "multiple groups" in this article includes "two groups" and "more than two groups".
[0035] Certain terms used to describe this application will be discussed below or elsewhere in this specification to provide additional guidance to those skilled in the art in describing the application.
[0036] like Figure 1 As shown, the network architecture of a 5G private network includes a user interface (UE), a network unit (RAN), a user plane network element (UPF), a multi-access edge computing (MEC), and a 5G core network. The 5G core network includes an AMF (Access and Mobility Management Function) and an SMF (Session Management Function) network element.
[0037] The terminal UE is a device capable of using the 5G network. After the device authenticates itself with the 5G core network, the SMF and UPF network elements establish a session tunnel for each terminal UE through the N4 interface. This session tunnel, also known as the N3 interface, is used for communication between the base station RAN and the UPF network elements.
[0038] The N3 interface uses the GTP protocol, which is based on the UDP (User Datagram Protocol) transport layer. After the 5G core network allocates a tunnel for the terminal UE, the terminal UE can transmit the load's service data through the allocated tunnel. For example... Figure 2 As shown, the GTP protocol network model, from bottom to top, includes the physical layer, data link layer, network layer (IP), transport layer (UDP), application layer (GTP), network layer (IP), transport layer, and application layer.
[0039] like Figure 3As shown, in existing traffic processing systems that employ hardware-based traffic splitting (i.e., network interface card (NIC) splitting), the hardware driver splits traffic using traffic 5-tuples. Packets with identical 5-tuples are assigned to the same NIC queue. Each NIC queue corresponds to a traffic processing engine. When traffic from the N3 interface enters the traffic processing system, it enters the same NIC queue due to identical 5-tuples and is processed by the same traffic processing engine, making concurrent processing of multiple terminals impossible.
[0040] like Figure 4 As shown, the N3 interface session management method in the 5G private network environment provided in this application is designed for high-concurrency traffic processing engines that can handle multiple sessions simultaneously. It includes the following steps:
[0041] S1. Use soft traffic splitting mode to access network card traffic.
[0042] S2. Parse the packet protocol of the incoming network card traffic to obtain the packet 5-tuple information and store it.
[0043] The five-tuple information includes source IP, destination IP, source port, destination port, and transport layer protocol. For messages where the corresponding source IP, destination IP, source port, destination port, or transport layer protocol is missing, the corresponding value is set to 0.
[0044] S3. Parse the GTP protocol.
[0045] When parsing a transport layer protocol (TLP), if the TTP protocol is identified as UDP and the destination port is 2152, it is initially determined to be the GTP protocol, and GTP protocol parsing is performed. If the parsing result does not meet the expectations of the GTP protocol, it is determined that the parsed message is not a GTP protocol message, and GTP protocol parsing needs to be exited.
[0046] S4. After the GTP protocol is parsed, the IP layer and transport layer of the GTP protocol payload are parsed to obtain the five-tuple information of the payload.
[0047] Store the source IP, destination IP, source port, destination port, and transport layer protocol of the payload. If the IP layer and transport layer information of the GTP protocol payload do not exist, set them to 0.
[0048] Replace the message quintuple information stored in step S2 with the payload quintuple information.
[0049] S5. Calculate the flow identifier ID based on the five-tuple information of the load, and allocate the packet to the corresponding flow processing engine based on the flow identifier ID.
[0050] The N3 interface session management method provided in this application for 5G private network environments adopts a soft traffic splitting mode to process N3 interface traffic. It performs tunnel stripping and recalculates the flow identifier ID based on the N3 interface traffic, and then allocates packets to the corresponding flow processing engine according to the flow identifier ID. This application is applicable to the management of N3 interface sessions in 5G private network environments, and is particularly suitable for high-concurrency processing of N3 traffic. This application can help security devices process 5G private network traffic at high speed and improve security protection capabilities.
[0051] Based on the N3 interface session management method in the 5G private network environment provided in this application, this application also provides an N3 interface session management system in the 5G private network environment, which includes a network card traffic collection module, a traffic parsing module, and a flow identifier ID processing module.
[0052] The network interface card (NIC) traffic collection module is used to collect network interface card (NIC) traffic from devices.
[0053] The traffic parsing module is used to parse the source IP, destination IP, source port, destination port, and transport layer protocol information of traffic. It is also used to parse the GTP protocol to obtain the source IP, destination IP, source port, destination port, and transport layer protocol information of the GTP payload.
[0054] The Flow Identifier ID processing module is used to calculate the Flow Identifier ID based on the five-tuple information of the GTP payload, and to allocate packets to the corresponding flow processing engine based on the Flow Identifier ID.
[0055] It should be noted that the N3 interface session management system in the 5G private network environment provided in the above embodiments and the N3 interface session management method embodiment in the 5G private network environment belong to the same concept. For details of its specific implementation process, please refer to the method embodiment, which will not be repeated here.
[0056] In an exemplary embodiment, this application also provides a computer storage medium, which is a computer-readable storage medium, such as a memory including a computer program, which can be executed by a processor to complete the N3 interface session management method in a 5G private network environment in any embodiment of this application.
[0057] The embodiments of this application described above can be implemented in various hardware, software codes, or combinations thereof. For example, embodiments of this application may also represent program code executing the above methods in a data signal processor. This application may also relate to various functions performed by a computer processor, digital signal processor, microprocessor, or field-programmable gate array. The processor described above can be configured to perform specific tasks according to this application, which are accomplished by executing machine-readable software code or firmware code defining the specific methods disclosed in this application. The software code or firmware code can be developed to represent different programming languages and different formats or forms. It can also represent software code compiled for different target platforms. However, the different code styles, types, and languages of the software code performing tasks according to this application and other types of configuration code do not depart from the spirit and scope of this application.
[0058] The above description is merely an illustrative embodiment of this application. Any equivalent changes and modifications made by those skilled in the art without departing from the concept and principles of this application shall fall within the scope of protection of this application.
Claims
1. A method for managing N3 interface sessions in a 5G private network environment, characterized in that, Includes the following steps: Accessing network card traffic using a soft traffic splitting mode; The traffic from the access network interface card is parsed, including: The incoming network interface card (NIC) traffic is parsed using packet protocol parsing to obtain packet 5-tuple information; the packet 5-tuple information includes source IP, destination IP, source port, destination port, and transport layer protocol; Parse the GTP protocol; The IP and transport layers of the GTP protocol payload are parsed to obtain the payload's 5-tuple information, which is then used to replace the message's 5-tuple information. The flow identifier ID is calculated based on the 5-tuple information of the load, and the packet is assigned to the corresponding flow processing engine based on the flow identifier ID.
2. The N3 interface session management method in a 5G private network environment according to claim 1, characterized in that, If the message protocol does not have a corresponding source IP, destination IP, source port, destination port, or transport layer protocol, set it to 0.
3. The N3 interface session management method in a 5G private network environment according to claim 1, characterized in that, The process of parsing the GTP protocol is as follows: The message transport layer protocol is parsed, and it is determined whether the message transport layer protocol is UDP and the destination port is 2152. If so, the message transport layer protocol is determined to be GTP protocol and GTP protocol is parsed.
4. The N3 interface session management method in a 5G private network environment according to claim 1, characterized in that, The five-tuple information of the payload includes the source IP, destination IP, source port, destination port, and transport layer protocol; for GTP protocol payloads, if there is no corresponding source IP, destination IP, source port, destination port, or transport layer protocol in the IP layer and transport layer, the corresponding value is set to 0.
5. An N3 interface session management system in a 5G private network environment, characterized in that, It includes a network interface card (NIC) traffic collection module, a traffic parsing module, and a flow identifier (ID) processing module; The network card traffic collection module is used to collect network card traffic of the device; The traffic parsing module is used to parse the source IP, destination IP, source port, destination port, and transport layer protocol information of the traffic. It is also used to parse the GTP protocol to obtain the source IP, destination IP, source port, destination port, and transport layer protocol information of the GTP payload; The Flow Identifier ID processing module is used to calculate the Flow Identifier ID based on the five-tuple information of the GTP payload, and to allocate the packets to the corresponding flow processing engines based on the Flow Identifier ID.
6. A storage medium, characterized in that, It stores a computer program, characterized in that, when the computer program is executed by a processor, it implements the N3 interface session management method in a 5G private network environment as described in any one of claims 1-4.
Citation Information
Patent Citations
User conversation level shunting method applied to Gn interface
CN102932842A
Data transmission method and device, network device and storage medium
CN112751871A